International · English

Data protection beyond the European Union

An overview of DPO and equivalent roles in key jurisdictions, and of how we support organisations operating internationally.

Overview by jurisdiction

Many jurisdictions outside the European Union now require a Data Protection Officer or an equivalent role, although the trigger, the title and the responsibilities differ. The summary below reflects the position known at the date of this page.

United Kingdom

The UK GDPR and the Data Protection Act 2018 keep DPO requirements equivalent to those of the EU GDPR, under the supervision of the Information Commissioner's Office. The Data (Use and Access) Act 2025 did not change the DPO requirement.

Switzerland

The revised Federal Act on Data Protection, in force since September 2023, makes the data protection advisor optional for private controllers. Appointing one allows a controller to consult the advisor, instead of the Federal Data Protection and Information Commissioner, on a high-risk impact assessment. Federal bodies must appoint an advisor.

Brazil

The LGPD requires controllers to appoint an encarregado, with an exemption for small processing agents. See the offers for Brazil.

South Africa

Under the Protection of Personal Information Act, the head of a private body is its Information Officer by default, and deputies may be designated. Information Officers must be registered with the Information Regulator.

Singapore

The Personal Data Protection Act requires every organisation to designate at least one individual to be responsible for ensuring compliance, commonly called the DPO, and to make that individual's business contact information available.

China

The Personal Information Protection Law requires a personal information protection officer where the volume of personal information processed reaches the threshold set by the Cyberspace Administration of China, currently the personal information of more than one million individuals.

India

The Digital Personal Data Protection Act 2023 is implemented by the rules notified in November 2025, with phased application. Significant Data Fiduciaries must appoint a DPO based in India, with that obligation applying from May 2027.

How we support you

For organisations operating across several of these jurisdictions, we build a privacy programme on a GDPR-grade baseline and adapt it to each local regime. The baseline can be aligned with ISO/IEC 27701:2025, now a standalone privacy information management system standard, to support certification where useful.

  • multi-jurisdiction assessment: a map of the obligations that apply in each country;

  • common programme: policies, records and procedures on a single baseline;

  • DPO or equivalent role: designation where required and a voluntary function where not;

  • international transfers: a framework for data flows between the EU and other jurisdictions.

See also: European Union · Países da CPLP · Iberoamérica

General information as at October 2026; laws in these jurisdictions change frequently and must be confirmed case by case. It does not constitute legal advice.

One privacy programme across jurisdictions

Request a proposal tailored to the countries where your organisation operates.